rivetkit
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents patterns for actors to ingest untrusted data and run generated code, creating a surface for indirect prompt injection. * Ingestion points: Untrusted data enters the agent context through durable queues (reference/actors/queues.md) and user-generated code deployment (reference/actors/ai-and-user-generated-actors.md). * Boundary markers: Most examples interpolate external data directly into prompts or workflows without explicit delimiters or bypass warnings. * Capability inventory: Actors have extensive capabilities including network access (fetch), database operations (SQLite), and system execution (execSync in deployment scripts). * Sanitization: While the documentation mentions schema validation using Zod, explicit sanitization or escaping of prompt data is not consistently demonstrated in the patterns provided.
Audit Metadata